ACF to REST API <= 3.3.4 - Insecure Direct Object Reference to Authenticated (Contributor+) ACF Field/Option Modification
medium
The ACF to REST API plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.3.4. This is due to insufficient capability checks in the update_item_permissions_check() method, which only verifies that the current user has the edit_posts capability without checking ob...
- CVSS:
- 4.3
- Affected:
- up to 3.3.4
- Fix:
- No patched version reported
- Disclosed:
- Jan 6, 2026
CVE-2025-12030 on NVD →
ACF to REST API <= 3.3.4 - Unauthenticated Information Exposure
medium
The ACF to REST API plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.4. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
- CVSS:
- 5.3
- Affected:
- up to 3.3.4
- Fix:
- No patched version reported
- Disclosed:
- Oct 20, 2025
CVE-2025-62979 on NVD →
ACF to REST API <= 3.2.0 - Insecure direct object reference via permalinks manipulation
high
An issue was discovered in the acf-to-rest-api plugin through 3.1.0 for WordPress. It allows an insecure direct object reference via permalinks manipulation, as demonstrated by a wp-json/acf/v3/options/ request that reads sensitive information in the wp_options table, such as the login and pass values. Issue was finall...
- CVSS:
- 7.5
- Affected:
- up to 3.2.0
- Fixed in:
- 3.3.0
- Disclosed:
- May 29, 2020
CVE-2020-13700 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database